Breaches: Page 11


  • City skyline in background, snowy highways in foreground
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Minnesota Department of Education exposed in MOVEit data breach

    The departments discovered on May 31 that 24 of its files on the MOVEit server had been accessed by an outside entity, including 95,000 student names in foster care across the state.

    By Anna Merod • June 14, 2023
  • sand dunes on the florida coast
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Ahead of summer holiday weekends, IT security leaders brace for deliberate cyber mischief

    Recent history shows holiday weekends and vacations provide an attack surface bonanza for threat actors.

    By May 26, 2023
  • close up programmer man hand typing on keyboard laptop for register data system or access password at dark operation room , cyber security concept - stock photo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    CISA updates ransomware guide 3 years after its debut

    The #StopRansomware guide, updated in partnership with the FBI, NSA and MS-ISAC, reflects aggressive new techniques used by threat actors, including double extortion.

    By May 24, 2023
  • Taco Bell exterior
    Image attribution tooltip
    Courtesy of Taco Bell
    Image attribution tooltip

    Yum Brands faces class action suits from employees after ransomware attack

    The Taco Bell and KFC operator is facing litigation after some personal data of company employees was stolen in the attack.

    By May 16, 2023
  • A group of people in shadow in front of a glowing square with a sign for Western Digital
    Image attribution tooltip
    Ian Tuttle / Stringer via Getty Images
    Image attribution tooltip

    Western Digital cyberattack not expected to have material impact on future earnings

    The company is coordinating with law enforcement while it continues a forensic investigation. 

    By May 15, 2023
  • Futuristic electronic semiconductor and telecommunication network concept
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Dragos says it thwarted extortion bid by known ransomware threat group

    The hackers accessed limited information by impersonating a new employee, and the cybersecurity firm warns some stolen data may be leaked.

    By May 11, 2023
  • Western Digital and Wired host "A Data-Driven Future: The Future of Mobility and Transportation in 2039."
    Image attribution tooltip
    Ian Tuttle via Getty Images
    Image attribution tooltip

    Western Digital confirms customer data accessed by hackers in attack

    The company has begun notifying customers about stolen data and expects to restore its online store next week.

    By May 8, 2023
  • Man using facial recognition technology on city street
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Google, Dashlane separately move to eliminate passwords

    In unrelated moves, the companies highlighted a growing effort to phase out dependence on passwords amid a rise in phishing attacks.

    By May 4, 2023
  • Abstract planet made up of squares.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    3CX threat actor named as company focuses on security upgrades, customer retention

    Mandiant attributed the supply chain attack to a North Korea-linked adversary that targeted systems using Windows-based malware.

    By April 12, 2023
  • Western Digital and Wired host "A Data-Driven Future: The Future of Mobility and Transportation in 2039."
    Image attribution tooltip
    Ian Tuttle via Getty Images
    Image attribution tooltip

    Western Digital restores local access to My Cloud Home customers following security breach

    The data storage company has provided limited updates to customers after disclosing the initial incident.

    By April 11, 2023
  • A Samsung flag flies outside the Samsung office on August 25, 2017 in Seoul, South Korea.
    Image attribution tooltip
    Chung Sung-Jun via Getty Images
    Image attribution tooltip

    Samsung employees leaked corporate data in ChatGPT: report

    Data privacy is a concern for companies with employees using ChatGPT’s web-based interface, as input data is used to train and improve the tool.

    By Lindsey Wilkinson • April 10, 2023
  • Employee in front of a laptop
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Broad MFA, rapid patching a must to stop cyberattacks, Marsh McLennan finds

    A study says organizations need to implement automated hardening techniques to protect systems against future data breaches. 

    By April 6, 2023
  • Trade secrets
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    IT security leaders still told to keep data breaches quiet, study finds

    Bitdefender research found 7 in 10 IT and security professionals in the U.S. have been asked to keep a breach confidential.

    By April 6, 2023
  • Teacher Giving Computer Science Lecture to Diverse Multiethnic Group of Female and Male Students in Dark College Room.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    3CX retains Mandiant to investigate supply chain attack with global reach

    Google has invalidated the 3CX software security certificate, and Microsoft software installer files can no longer be downloaded via Chrome. A new installer and certificate are in development.

    By March 31, 2023
  • Exclamation mark depicted over code.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    CISA summons outside tips to alert victims of early-stage ransomware

    Post-breach notifications might seem too late for victim organizations, but swift action can prevent ransomware and data exfiltration.

    By March 27, 2023
  • Wawa
    Image attribution tooltip
    Retrieved from Wawa website.
    Image attribution tooltip

    Wawa to pay up to $28.5M in data breach settlement

    The chain’s latest payout will go to the financial institutions involved in the 2019 incident, continuing a series of payments it has made to customers and states over the past year.

    By Brett Dworski • March 16, 2023
  • Image attribution tooltip
    Chip Somodevilla via Getty Images
    Image attribution tooltip

    Blackbaud to pay $3M to settle SEC charges of a misleading ransomware investigation

    The regulator said the cloud-based software provider made misleading disclosures about the scope of a 2020 ransomware attack. 

    By March 10, 2023
  • An illustration of personal info cards passing through a medical cross shape opening in a person's chest.
    Image attribution tooltip

    Illustration: Yann Bastard for Industry Dive 

    Image attribution tooltip
    Deep Dive

    Hacking healthcare: With 385M patient records exposed, cybersecurity experts sound alarm on breach surge

    Healthcare companies must harden their defenses, but it may require regulators and lawmakers to raise the bar on security standards, experts say.

    By March 10, 2023
  • Connection network in dark servers data center room storage systems.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Worried about data breaches? Blame the information sector

    Three in five records exposed in a data breach last year came from software, telecom, data processing and web hosting companies, Flashpoint found.

    By March 9, 2023
  • Double exposure shot of backside of a computer and red binary codes.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Insurance holding company Group 1001 says operations restored after ransomware attack

    The company did not pay a ransom following a February attack that disrupted operations at several of its member companies.

    By March 7, 2023
  • Post-its on a glass wall
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    LastPass aftermath leaves long to-do list for business customers

    Organizations using the password manager are exposed after a major breach compromised credentials and, potentially, business secrets.

    By March 6, 2023
  • Aerial view of a winding mountain road.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    LastPass breach timeline: How a monthslong cyberattack unraveled

    A threat actor evaded detection for months and blended in with legitimate activity after targeting 1 of 4 engineers with access to keys to the kingdom.

    By Updated March 3, 2023
  • Computer engineer working with a computer interface in a factory.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    CISA red team cracks a critical infrastructure provider’s defenses, a lesson in lateral access

    The voluntary assessment raises concerns as the unnamed organization with a mature security program was unable to detect simulated actors moving laterally across its systems for months.

    By March 1, 2023
  • A photo illustration of LastPass logos on a hard drive disk held in someone's hand.
    Image attribution tooltip
    Leon Neal via Getty Images
    Image attribution tooltip

    LastPass compromise grew worse after DevOps engineer targeted for encryption key

    A threat actor used data from multiple breaches and a vulnerability on a high-level employee’s home computer to steal customer passwords.

    By Feb. 28, 2023
  • A password field reflected on a eye.
    Image attribution tooltip
    Leon Neal via Getty Images
    Image attribution tooltip

    Phishing takes financial bite out of more victim organizations

    The majority of organizations, 84%, experienced at least one successful phishing attack in 2022, Proofpoint research found.

    By Feb. 28, 2023